Malicious TRAE Extension Uses Ethereum Smart Contracts for Dynamic C2 Configuration Updates
2026-07-21 08:53

Woofun AI reports that the Slow Mist security team identified a malicious extension named 'juannegro.solidity' in the TRAE IDE market. Disguised as a legitimate Solidity plugin, this cross-platform malware dropper establishes persistence upon IDE startup and utilizes Ethereum smart contracts to store and retrieve dynamic command-and-control (C2) configurations. Although removed from Open VSX, the extension remained accessible via the TRAE market as of July 18. Attackers can modify C2 endpoints and malicious payloads without republishing the extension. Slow Mist advises users to uninstall the extension immediately and verify system integrity.

Disclaimer: Views are the author's own and do not represent the platform. Do not reproduce without permission. Content is for reference only, not investment advice. Trade at your own risk.
Tags:
TRAE
juannegro.solidity
Open VSX
Slow Mist
Ethereum
Share:
back